HeadCrab is a custom Redis-targeting malware family used to compromise internet-exposed Redis servers and conscript them into a botnet primarily associated with illicit cryptocurrency mining. Activity attributed to HeadCrab has been observed since at least 2021, and the malware has been linked to large-scale server compromise campaigns affecting well over a thousand Redis instances.
The malware is implemented as a malicious Redis module and is notable for its emphasis on stealth, in-memory execution, and abuse of legitimate Redis functionality. Early variants compromised exposed Redis servers by abusing Redis replication, using master-replica synchronization to deliver and load a malicious module. Once active, HeadCrab operated largely filelessly, minimized disk artifacts, tampered with or truncated Redis logs, and used memory-backed execution mechanisms to hinder forensic recovery and signature-based detection.
HeadCrab exposes attacker-controlled functionality through malicious Redis command handling. Earlier variants introduced custom Redis commands to support remote command execution, encrypted command-and-control, configuration manipulation, and other post-compromise operations. The malware also overrode selected native Redis commands to obstruct inspection and interfere with defensive analysis. Reported capabilities include execution of shell commands, encrypted communications, persistence-oriented configuration changes, and memory-only loading of additional components.
A later evolution, commonly referred to as HeadCrab 2.0, increased stealth by replacing direct on-disk deployment of the main payload with a loader-based approach that receives malware content over the Redis communication channel and stores it in a fileless location on the host. It also abandoned easily detectable custom command names in favor of abusing the legitimate Redis MGET command for covert command-and-control, while preserving normal behavior for benign users. This version additionally manipulated lower-level Redis internals to redirect command processing, making detection more difficult.
HeadCrab is associated with a threat actor of the same name and is focused on Linux-based Redis server environments. Its operational objective has been characterized primarily as resource hijacking for cryptomining, but its command execution and remote-control features make it a broader post-exploitation platform for compromised Redis infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
“The dynamic loader can be used to execute process under its name… bypass security solution… Since the dynamic loader is a legitimate binary…”
“logs are deleted using the Redis module framework and API… deletes the Redis log file and empties it… truncating it to size 0.”
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that infects Redis servers, disables protection features, and hijacks them for Monero cryptocurrency mining.
Custom Redis-targeting malware used to compromise Redis servers. The newer version uses a fileless loader, hooks Redis command handling, and hides C2 traffic inside normal Redis commands such as MGET to evade detection and maintain covert control of infected servers.
Custom malicious Redis module loaded via Redis replication (SLAVEOF) and MODULE LOAD to provide encrypted C2, command execution, tunneling, fileless payload staging via memfd, log deletion, persistence (e.g., systemd/init scripts), and resource hijacking for Monero mining; includes capabilities to load kernel modules from memory and steal SSH keys via LD_PRELOAD-based service masquerading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.